📦 Fortiportal

by Fortinet

🔍 What is Fortiportal?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-24470

HIGH CVSS 8.6 Feb 11, 2025

CVE-2025-24470 is an Improper Resolution of Path Equivalence vulnerability in FortiPortal that allows remote unauthenticated attackers to retrieve source code via crafted HTTP requests. This affects F...

CVE-2021-32589

HIGH CVSS 8.1 Dec 19, 2024

A use-after-free vulnerability in FortiManager and FortiAnalyzer's fgfmsd daemon allows remote unauthenticated attackers to execute arbitrary code as root by sending specially crafted requests to the ...

CVE-2024-40593

MEDIUM CVSS 6.0 Dec 11, 2025

This vulnerability allows authenticated administrators on affected Fortinet devices to retrieve certificate private keys via the admin shell. This affects FortiAnalyzer, FortiManager, FortiOS, and For...

CVE-2025-54838

MEDIUM CVSS 6.8 Dec 9, 2025

An incorrect authorization vulnerability in FortiPortal versions 7.4.0 through 7.4.5 allows authenticated attackers to reboot shared FortiGate devices via crafted HTTP requests. This affects organizat...

CVE-2024-40590

MEDIUM CVSS 4.8 Mar 14, 2025

This vulnerability allows man-in-the-middle attackers to intercept and tamper with encrypted communications between FortiPortal and FortiManager/FortiAnalyzer/SMTP servers due to improper certificate ...

CVE-2024-35278

MEDIUM CVSS 4.3 Jan 14, 2025

This SQL injection vulnerability in Fortinet FortiPortal allows authenticated attackers to view server-side SQL queries by submitting specially crafted HTTP requests. It affects FortiPortal versions 7...

CVE-2024-26011

MEDIUM CVSS 5.3 Nov 12, 2024

This vulnerability allows unauthenticated attackers to execute arbitrary code or commands on affected Fortinet devices by sending specially crafted packets. It affects multiple Fortinet products inclu...

CVE-2024-31495

MEDIUM CVSS 4.3 Jun 11, 2024

This SQL injection vulnerability in Fortinet FortiPortal allows privileged users to execute unauthorized SQL commands through the report download functionality, potentially accessing sensitive informa...